Reference — generated from the toolkit
Source of truth: toolkit/registers/README.md. Edit it there; this page is regenerated on build.
Registers
Living registers — each a canonical list with a fixed schema, every entry linked to its evidence. A finding that isn't in the right register doesn't exist.
Schemas are defined; rows are populated as their source activities run (mostly STOP). Defined: tech-debt-register.md, security-debt-register.md, eol-inventory.md, security-exceptions.md. Still to define:
| Register | Populated by | Owner |
|---|---|---|
| Client-commitment register | STOP client triage | Delivery |
| Tech-debt register | tech-debt audit | Engineering |
| Security-debt register | security-gap assessment | Security |
| Risk-acceptance records | any gate / STOP exit | Engineering + Security |
| Security exception / waiver register | gate waivers | Security |
| Client & market signal register | Commercial + Support | Product |
| Gate-waiver log | all gates | gate owners |
Waivers and accepted risks always carry a named owner and a hard expiry after which the gate re-blocks.